Live data from Hacker News

AWS Shield – Managed DDoS Protection

aws.amazon.com

1–10 of 79 posts

Re: AWS Shield – Managed DDoS Protection

#2
Finally. The basic offer is something a lot of other providers already have. Not sure about the advanced one. Sounds quite expensive. $3,000/month plus extra traffic costs.

And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).

Re: AWS Shield – Managed DDoS Protection

#3
post #2

Finally. The basic offer is something a lot of other providers already have. Not sure about the advanced one. Sounds quite expensive. $3,000/month plus extra traffic costs. And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).

Pricing Example 4: AWS Shield Advanced For Amazon CloudFront

Let’s assume that you deploy an Amazon CloudFront Distribution in front of the Application Load Balancer from Example 3. You then enable AWS Shield Advanced protection for your Amazon CloudFront Distribution, and remove it from your Application Load Balancer. (If you have deployed Amazon CloudFront in front of Application Load Balancer, you only need to enable protection for Amazon CloudFront).

Under this scenario, at the end of the month, you will pay the AWS Shield Advanced monthly fee of $3,000. In addition to the monthly fee, you will be charged the AWS Shield Advanced usage based fee of $25 for the 1,000 GB of Regional Data Transfer out at $0.025 per GB. Your total AWS Shield charges for the month will be $3,000 + $25 = $3,025.

In addition, you will pay standard Application Load Balancer and Amazon CloudFront fees as described in the Application Load Balancer Pricing and Amazon CloudFront Pricing pages.

Re: AWS Shield – Managed DDoS Protection

#5
post #2

Finally. The basic offer is something a lot of other providers already have. Not sure about the advanced one. Sounds quite expensive. $3,000/month plus extra traffic costs. And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).

> $3,000/month plus extra traffic costs.

As if their existing margins on bandwidth aren't high enough.

Re: AWS Shield – Managed DDoS Protection

#6
post #4

I've been saying for years that AWS has secret DDOS protection. Never confirmed, but I'm pretty sure the basic level is just them admitting that they've always had that service.

I wondered about this as well. At the very least, AWS provided admin protection during a DDOS attack. Unlike other providers their administration portion of the website was always online and accessible. This was an important and unsung benefit to using AWS.

Re: AWS Shield – Managed DDoS Protection

#7
post #2

Finally. The basic offer is something a lot of other providers already have. Not sure about the advanced one. Sounds quite expensive. $3,000/month plus extra traffic costs. And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).

> Finally. The basic offer is something a lot of other providers already have.

Sure, protections like what OVH "already offers" when a DDOS attack downs their entire administrative portal?

It's clear to heavy AWS users that Amazon was already providing certain DDoS protections before this announcement.

Re: AWS Shield – Managed DDoS Protection

#8
> AWS Shield Advanced comes with “DDoS cost protection”, a safeguard from scaling charges as a result of a DDoS attack that cause usage spikes on Elastic Load Balancing (ELB), Amazon CloudFront or Amazon Route 53. If any of these services scale up in response to a DDoS attack, AWS will provide service credits for charges due to usage spikes.

This is a very big deal!

Re: AWS Shield – Managed DDoS Protection

#9
post #2

Finally. The basic offer is something a lot of other providers already have. Not sure about the advanced one. Sounds quite expensive. $3,000/month plus extra traffic costs. And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).

That's $2000/month cheaper than Cloudflare Enterprise. I imagine they have the same target customer?

Re: AWS Shield – Managed DDoS Protection

#10
post #4

I've been saying for years that AWS has secret DDOS protection. Never confirmed, but I'm pretty sure the basic level is just them admitting that they've always had that service.

This is not true. The reality is that they have never had a "secret strat" for dealing with DDoS attacks except to pass the buck to their customers. And the lack of a clearly defined policy, combined with their exorbitant bandwidth costs, has made it far too dangerous to anyone without a massive budget to build services on their infrastructure.

They have decided to "resolve" this problem by using it as an opportunity to further gouge their customers on bandwidth (which is already 12x+ more expensive than market rate for IP transit), instead of absorbing it into their existing cost structure. Which still would have meant their bandwidth was overpriced, and still would be way higher than what you can get pretty much everywhere else.

For a contrast, OVH provides this protection as an included feature in all of their offerings. Before everyone writes it off as junk in comparison to the glorious AWS black box (AWS is amazing at marketing), bear in mind that the OVH scrubber just took a terabit DDoS attack against it and survived: http://www.securityweek.com/hosting-provider-ovh-hit-1-tbps-...

OVH correctly realizes that the only way to solve this problem is to make sure everybody gets access to it. Otherwise you're just encouraging the democratization of censorship for those without the means to protect themselves against it. I hope the "cloud" providers follow their example.

Post reply on HN